Skip to content
Back to skills

Abnormal

ASecurity

Expert agent for Abnormal Security. Covers API-based behavioral AI email protection, BEC detection, vendor email compromise, account takeover, and native M365/Google Workspace integration without MX changes. WHEN: \"Abnormal Security\", \"Abnormal AI\", \"behavioral email security\", \"BEC detection\", \"vendor email compromise\", \"VEC\", \"API email security\", \"account takeover email\", \"Abnormal SIEM\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
securityrustgonodeazuregitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill abnormal --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Abnormal?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Abnormal
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-abnormal/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-abnormal)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: abnormal
description: "Expert agent for Abnormal Security. Covers API-based behavioral AI email protection, BEC detection, vendor email compromise, account takeover, and native M365/Google Workspace integration without MX changes. WHEN: \"Abnormal Security\", \"Abnormal AI\", \"behavioral email security\", \"BEC detection\", \"vendor email compromise\", \"VEC\", \"API email security\", \"account takeover email\", \"Abnormal SIEM\"."
license: MIT
---

# Abnormal Security

This skill covers Abnormal Security's AI-native email security platform. Abnormal uses behavioral AI and API integration (no MX change required) to detect sophisticated attacks that evade traditional secure email gateways — primarily BEC, vendor email compromise, supply chain fraud, and account takeover.

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Deployment** — API integration, permissions, M365/Google setup
   - **BEC/VEC detection** — Behavioral AI, attack signals, detection tuning
   - **Account takeover (ATO)** — Detection, remediation, signals
   - **Investigation** — Case analysis, threat log review, SIEM integration
   - **Policy/configuration** — Detection thresholds, safe senders, remediation actions
   - **Reporting** — Attack briefings, SOC feed, executive reporting

2. **Identify the mail platform** — Abnormal supports Microsoft 365 and Google Workspace. Deployment and detection capabilities vary.

3. **Apply behavioral AI context** — Abnormal's core differentiation is behavioral modeling. Understanding the signals that drive its detections is key to investigation and tuning.

## Deployment Architecture

### No MX Change Required

Abnormal connects entirely via platform APIs — no MX record modification, no DNS change, no disruption to mail flow.

**Integration method:**
- **M365:** Microsoft Graph API (via Azure App Registration with admin consent)
- **Google Workspace:** Gmail API + Directory API (via Service Account with domain-wide delegation)

**Deployment time:** 30-60 minutes for initial connection; detection and baselining begin immediately; full behavioral model maturity in 7-14 days.

### M365 Integration (Microsoft Graph API)

**Required Azure App Registration permissions:**
```
Microsoft Graph - Application Permissions:
- Mail.ReadWrite            # Read and delete messages (for remediation)
- Mail.Read                 # Read message content for analysis
- MailboxSettings.Read      # Detect forwarding rules, OOF, delegates
- User.Read.All             # User directory, roles, attributes
- Group.Read.All            # Group membership (detect unusual recipients)
- AuditLog.Read.All         # Sign-in logs for ATO detection
- Directory.Read.All        # Org structure (reporting relationships)
- SecurityEvents.Read.All   # Microsoft security alerts correlation
- Policy.Read.All           # Conditional access, MFA status
```

**Data accessed:**
- Email messages (metadata + content for analysis)
- User sign-in logs (for ATO detection via impossible travel, new locations)
- Mailbox rules (detect suspicious forwarding rules post-compromise)
- Calendar, Teams (extended behavioral context for Abnormal's higher tiers)

### Google Workspace Integration

**Required Service Account scopes:**
```
https://www.googleapis.com/auth/gmail.readonly        # Read messages
https://www.googleapis.com/auth/gmail.modify          # Remediate messages
https://www.googleapis.com/auth/admin.directory.user.readonly  # User directory
https://www.googleapis.com/auth/admin.reports.audit.readonly   # Audit logs
```

**Domain-wide delegation** required — the service account must be authorized to act on behalf of all users in the organization.

## Behavioral AI Detection Model

### Identity Graph and Behavioral Baseline

Abnormal builds a unique behavioral profile for every identity in the organization (employees, contractors, vendors, third parties who email your users).

**Per-identity signals profiled:**
- Typical email communication patterns (who they email, frequency, times)
- Writing style (vocabulary, sentence structure, formality)
- Geographic sending locations
- Device and browser fingerprints
- Time-of-day patterns
- Communication relationship graph (have these two people emailed before?)
- Subject line patterns
- Link and attachment sending behaviors

**Organization-level signals:**
- Organizational hierarchy (reporting relationships from directory)
- Finance team members and roles
- Common payment/invoice processes
- Internal communication norms

**Baselining period:** Abnormal analyzes historical email to build baselines. New messages are scored against this model.

### BEC Detection Signals

Abnormal's BEC detection identifies attacks based on behavioral deviation, not signatures.

**Social engineering signals:**
- Urgency + secrecy combination ("please handle this before EOD, don't mention to others")
- Unusual action request (wire transfer, gift cards, invoice payment change)
- Financial keywords in context of unusual sender relationship
- Request to take action outside normal business processes

**Identity signals:**
- Sender's writing style deviates significantly from established baseline
- Message tone inconsistent with prior communication history
- Sender's normal patterns (location, time, device) not matching this message
- Reply-to address different from From address (common in CEO fraud)

**Relationship signals:**
- No prior communication between sender and recipient
- Low-frequency relationship suddenly sending high-importance financial request
- Message references a recent company event (acquisition, merger) — indicates targeted research

**Technical signals:**
- SPF/DKIM/DMARC failures (surface to detection model, though Abnormal also catches authenticated BEC)
- Domain lookalike (Abnormal includes character analysis of sender domain)
- Free email account impersonating executive (exec@gmail.com instead of exec@company.com)

### Vendor Email Compromise (VEC) Detection

VEC is among the hardest attacks to detect because the attacker has compromised a legitimate vendor's email account — DKIM passes, the domain is real, the sender is trusted.

**Abnormal's VEC approach:**

**Vendor profile baseline:**
Abnormal builds behavioral models for frequent external senders, not just internal identities. The model learns:
- How vendor X normally formats invoice emails
- What attachments they typically send
- Their normal account numbers and payment references
- Communication patterns with your AP team

**VEC attack signals:**
- Account number, routing number, or payment instructions changed from established pattern
- Request to update payment details (deviates from established vendor behavior)
- Message sent from a new geographic location or IP range
- Slight writing style change (attacker's style vs. victim's normal style)
- Request urgency or deadline unusual for this vendor relationship
- New email thread referencing invoice (not a reply to existing thread)

**VEC investigation flow:**
1. Abnormal flags message as VEC risk with explanation
2. Analyst reviews: What changed from established pattern?
3. Verify via out-of-band channel (phone vendor using known number)
4. If confirmed: Remediate message, alert AP team, notify vendor

### Account Takeover (ATO) Detection

Abnormal monitors post-authentication behaviors to detect when a legitimate account has been compromised.

**ATO trigger signals:**
- **Impossible travel:** Login from city A, then city B, within a timeframe impossible by travel (e.g., New York + London within 2 hours)
- **New country:** Login from a country the user has never accessed from
- **New ASN/IP:** Access from an ISP or IP range not seen in user's history
- **Anonymous network:** Login through Tor exit node, known VPN exit IP, or datacenter IP
- **MFA bypass patterns:** Conditional access policy change, legacy authentication enabled
- **Unusual session properties:** Unusual user agent, new device fingerprint

**Post-compromise indicators:**
- Inbox rule created: Forward all email to external address
- Inbox rule created: Delete messages containing "phish", "fraud", "security", "unusual" (attacker hiding evidence)
- Delegate access granted to external account
- Mass email sent to external recipients
- OAuth app granted mail access permissions
- Password change or MFA device added

**Abnormal's ATO response:**
- Alert generated with full compromise chain (login signals + behavioral changes)
- Recommended actions: Disable user session, force password reset, review inbox rules
- Integration with identity providers (Entra ID, Okta) for automated account suspension

## Attack Analysis and Case Management

### Abnormal Portal — Case Review

Each detected attack creates a case in the Abnormal portal with:

**Attack summary:**
- Attack type (BEC, VEC, ATO, phishing, malware, etc.)
- Reason for detection (which signals triggered)
- Confidence score
- Remediation status

**Why Abnormal flagged it:**
Abnormal provides plain-language explanation of detection reasoning:
> "This message was flagged because the sender 'CEO Name' has never previously emailed the recipient 'AP Manager', the request involves a wire transfer of $47,000, and the reply-to address (attacker@gmail.com) differs from the From address."

**Message details:**
- Full email content (headers, body, attachments)
- Authentication results (SPF/DKIM/DMARC)
- Sender behavioral profile deviation
- Similar historical messages from sender for comparison

**Timeline view:**
Multi-stage attacks (e.g., initial reconnaissance, then wire transfer request) shown in a unified timeline.

### Remediation Actions

**Automatic remediation:**
Abnormal can automatically move detected attacks to junk or delete them, configurable by attack type and confidence threshold.

```
High-confidence BEC (score > 90): Auto-move to junk
High-confidence phishing with malware: Auto-delete
Medium-confidence: Hold for analyst review
```

**Manual remediation:**
From the case, analysts can:
- Move message to junk or delete
- Add sender to blocklist
- Trigger user notification
- Initiate ATO response workflow

**Remediation API:**
```
POST /v1/cases/{caseId}/actions/remediate
Authorization: Bearer {api_key}
Body: {"action": "move_to_junk"}
```

## SIEM and SOAR Integration

### Abnormal Security API

REST API for integration with SIEM/SOAR platforms.

**Authentication:**
```
Authorization: Bearer {api_key}
```
API keys generated in Abnormal portal under Settings → Integrations.

**Key endpoints:**
```
GET  /v1/cases                          # List attack cases
GET  /v1/cases/{caseId}                # Case details
GET  /v1/cases/{caseId}/messages        # Messages in case
POST /v1/cases/{caseId}/actions         # Remediate case
GET  /v1/threats                        # Threat feed
GET  /v1/employee_change_events         # ATO-related identity events
```

**Webhooks:**
Abnormal supports webhooks for real-time alert delivery to SIEM:
```
POST {webhook_url}
Payload: {case_id, attack_type, severity, detection_time, remediation_status}
```

**SIEM integrations (native):**
- Splunk (Abnormal App for Splunk)
- Microsoft Sentinel (Abnormal connector)
- Palo Alto Cortex XSOAR (playbook integration)
- ServiceNow (ticket creation)

### SOC Email Threat Feed

Abnormal provides a SOC-level threat feed with:
- All detected attacks with full context
- IOCs (sender IPs, domains, URLs, file hashes)
- MITRE ATT&CK tactic mapping for each attack
- Time to detect and time to remediate metrics

**Splunk integration example:**
```
index=abnormal_security source="abnormal:cases"
| where attack_type="BEC"
| stats count by sender_domain
| sort -count
```

## Reporting and Executive Visibility

### Attack Briefings

Abnormal generates automated attack briefings (daily/weekly) showing:
- Total attacks detected and remediated
- BEC attacks by type (wire fraud, gift cards, credential phishing)
- Estimated financial risk prevented (calculated from attack context)
- Top targeted employees
- Attack trend vs. previous period

### CISO Dashboard

Board-ready metrics:
- Email risk posture score
- BEC risk by department
- Top 10 most targeted employees
- Vendor ecosystem risk (VEC exposure)
- ATO events detected

## Abnormal vs. SEG Comparison

| Capability | SEG (Proofpoint/Mimecast) | Abnormal |
|---|---|---|
| Deployment | MX record change required | API only, no MX change |
| Detection method | Signature + heuristics + sandbox | Behavioral AI |
| BEC (display name) | Rule-based, limited | Behavioral — catches sophisticated variants |
| Vendor email compromise | Limited (sender is legitimate) | Core strength |
| Account takeover | Cannot detect | Detects via behavioral + sign-in analysis |
| Internal email scanning | No (only processes inbound via MX) | Yes (full internal visibility via API) |
| URL rewriting | Yes | No (post-delivery model) |
| Pre-delivery blocking | Yes | No (post-delivery detection + remediation) |
| On-prem Exchange support | Yes | No (requires M365 or Google Workspace API) |

**Best practice:** Deploy Abnormal alongside EOP/Defender for O365 (or alongside a SEG). The layers complement each other — SEG handles bulk spam, malware, and signature-based phishing; Abnormal handles behavioral BEC, VEC, and ATO that evades signature-based tools.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…